Deploying Security-Aware Service Function Chains with Asymmetric Dedicated Protection
Danyang Zheng, Shaohua Cao, Honghui Xu, Xiaojun Cao · 2024
In the emerging applications of edge computing (e.g., unmanned factories and meta-verse), network requests are required to be securely and reliably delivered in the form of service function chains (SFCs). To enhance security, security-aware SFs are employed in the SFC, and this type of SFC is referred to as the security-aware SFC (S-SFC). For reliability, service providers can employ a dedicated backup SFC to protect the primary one. However, no existing works addressed the SFC deployment mechanisms that jointly consider SFC reliability and security. For this, here, we investigate the problem of jointly embedding and protecting a security-aware SFC. To efficiently compose, embed, and protect an S-SFC, we propose the S-SFC asymmetric protection concept, which allows the primary and backup SFCs not necessarily to follow an identical structure as the traditional SFC dedicated protection does. Next, we formulate the problem of S-SFC composing, embedding, and protection (S-SFCEP) and prove its NP-hardness. To tackle this problem, we formulate an efficient algorithm, namely, sub-chain-based S-SFC deployment (SCB-SD). Our extensive simulation results show that the proposed SCB-SD outperforms the state-of-the-art benchmarks by an average of 13.86% and 23.19%, respectively.